2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47253CRITICAL9.8Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques...
CVE-2023-38407HIGH7.5bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast pars...
CVE-2023-38406CRITICAL9.8bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
CVE-2023-4625MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/i...
CVE-2023-32840MEDIUM6.5In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio...
CVE-2023-32839MEDIUM6.7In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalati...
CVE-2023-32838MEDIUM6.7In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalati...
CVE-2023-32837HIGH7.8In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2023-32836MEDIUM6.7In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p...
CVE-2023-32835MEDIUM6.7In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privi...
CVE-2023-32834MEDIUM6.7In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege...
CVE-2023-32832HIGH7In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privileg...
CVE-2023-32825MEDIUM5.5In bluethooth service, there is a possible out of bounds reads due to improper input validation. This could lead to loca...
CVE-2023-32818MEDIUM6.7In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege...
CVE-2023-20702HIGH7.5In 5G NRLC, there is a possible invalid memory access due to lack of error handling. This could lead to remote denial of...
CVE-2023-46802MEDIUM5.5e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configurat...
CVE-2023-47272MEDIUM6.1Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used fo...
CVE-2023-47271MEDIUM5.3PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other pr...
CVE-2023-47260MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
CVE-2023-47259MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
CVE-2023-47258MEDIUM6.1Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
CVE-2023-47249MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in Ic...
CVE-2023-46981CRITICAL9.8SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted scrip...
CVE-2023-46964MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attac...
CVE-2023-46963MEDIUM5.3An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attack...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now